|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* Winbind ID Mapping Plugin
|
|
Packit |
5f9837 |
* Copyright (C) 2012 Jeff Layton (jlayton@samba.org)
|
|
Packit |
5f9837 |
*
|
|
Packit |
5f9837 |
* This program is free software; you can redistribute it and/or modify
|
|
Packit |
5f9837 |
* it under the terms of the GNU General Public License as published by
|
|
Packit |
5f9837 |
* the Free Software Foundation; either version 3 of the License, or
|
|
Packit |
5f9837 |
* (at your option) any later version.
|
|
Packit |
5f9837 |
*
|
|
Packit |
5f9837 |
* This program is distributed in the hope that it will be useful,
|
|
Packit |
5f9837 |
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
Packit |
5f9837 |
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
Packit |
5f9837 |
* GNU General Public License for more details.
|
|
Packit |
5f9837 |
*
|
|
Packit |
5f9837 |
* You should have received a copy of the GNU General Public License
|
|
Packit |
5f9837 |
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
#ifdef HAVE_CONFIG_H
|
|
Packit |
5f9837 |
#include "config.h"
|
|
Packit |
5f9837 |
#endif /* HAVE_CONFIG_H */
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
#include <stdint.h>
|
|
Packit |
5f9837 |
#include <endian.h>
|
|
Packit |
5f9837 |
#include <string.h>
|
|
Packit |
5f9837 |
#include <errno.h>
|
|
Packit |
5f9837 |
#include <stdbool.h>
|
|
Packit |
5f9837 |
#include <stdio.h>
|
|
Packit |
5f9837 |
#include <stdlib.h>
|
|
Packit |
5f9837 |
#include <wbclient.h>
|
|
Packit |
5f9837 |
#include <limits.h>
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
#include "cifsidmap.h"
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
static const char **plugin_errmsg;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
|
|
Packit |
5f9837 |
* csid to the wsid, while converting the subauthority fields from LE.
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
static void
|
|
Packit |
5f9837 |
csid_to_wsid(struct wbcDomainSid *wsid, const struct cifs_sid *csid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
int i;
|
|
Packit |
5f9837 |
uint8_t num_subauth = (csid->num_subauth <= WBC_MAXSUBAUTHS) ?
|
|
Packit |
5f9837 |
csid->num_subauth : WBC_MAXSUBAUTHS;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wsid->sid_rev_num = csid->revision;
|
|
Packit |
5f9837 |
wsid->num_auths = num_subauth;
|
|
Packit |
5f9837 |
for (i = 0; i < NUM_AUTHS; i++)
|
|
Packit |
5f9837 |
wsid->id_auth[i] = csid->authority[i];
|
|
Packit |
5f9837 |
for (i = 0; i < num_subauth; i++)
|
|
Packit |
5f9837 |
wsid->sub_auths[i] = le32toh(csid->sub_auth[i]);
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
|
|
Packit |
5f9837 |
* wsid to the csid, while converting the subauthority fields to LE.
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
static void
|
|
Packit |
5f9837 |
wsid_to_csid(struct cifs_sid *csid, struct wbcDomainSid *wsid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
int i;
|
|
Packit |
5f9837 |
uint8_t num_subauth = (wsid->num_auths <= SID_MAX_SUB_AUTHORITIES) ?
|
|
Packit |
5f9837 |
wsid->num_auths : SID_MAX_SUB_AUTHORITIES;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
csid->revision = wsid->sid_rev_num;
|
|
Packit |
5f9837 |
csid->num_subauth = num_subauth;
|
|
Packit |
5f9837 |
for (i = 0; i < NUM_AUTHS; i++)
|
|
Packit |
5f9837 |
csid->authority[i] = wsid->id_auth[i];
|
|
Packit |
5f9837 |
for (i = 0; i < num_subauth; i++)
|
|
Packit |
5f9837 |
csid->sub_auth[i] = htole32(wsid->sub_auths[i]);
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
int
|
|
Packit |
5f9837 |
cifs_idmap_sid_to_str(void *handle __attribute__ ((unused)),
|
|
Packit |
5f9837 |
const struct cifs_sid *csid, char **string)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
int rc;
|
|
Packit |
5f9837 |
wbcErr wbcrc;
|
|
Packit |
5f9837 |
char *domain = NULL;
|
|
Packit |
5f9837 |
char *name = NULL;
|
|
Packit |
5f9837 |
enum wbcSidType sntype;
|
|
Packit |
5f9837 |
struct wbcDomainSid wsid;
|
|
Packit |
5f9837 |
size_t len;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
csid_to_wsid(&wsid, csid);
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wbcrc = wbcLookupSid(&wsid, &domain, &name, &sntype);
|
|
Packit |
5f9837 |
if (!WBC_ERROR_IS_OK(wbcrc)) {
|
|
Packit |
5f9837 |
*plugin_errmsg = wbcErrorString(wbcrc);
|
|
Packit |
5f9837 |
return -EIO;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
/* +1 for '\\' and +1 for NULL terminator */
|
|
Packit |
5f9837 |
len = strlen(domain) + 1 + strlen(name) + 1;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
*string = malloc(len);
|
|
Packit |
5f9837 |
if (!*string) {
|
|
Packit |
5f9837 |
*plugin_errmsg = "Unable to allocate memory";
|
|
Packit |
5f9837 |
rc = -ENOMEM;
|
|
Packit |
5f9837 |
goto out;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
rc = snprintf(*string, len, "%s\\%s", domain, name);
|
|
Packit |
5f9837 |
if (rc >= (long)len) {
|
|
Packit |
5f9837 |
free(*string);
|
|
Packit |
5f9837 |
*plugin_errmsg = "Resulting string was truncated";
|
|
Packit |
5f9837 |
*string = NULL;
|
|
Packit |
5f9837 |
rc = -EIO;
|
|
Packit |
5f9837 |
} else {
|
|
Packit |
5f9837 |
rc = 0;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
out:
|
|
Packit |
5f9837 |
wbcFreeMemory(domain);
|
|
Packit |
5f9837 |
wbcFreeMemory(name);
|
|
Packit |
5f9837 |
return rc;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
int
|
|
Packit |
5f9837 |
cifs_idmap_str_to_sid(void *handle __attribute__ ((unused)),
|
|
Packit |
5f9837 |
const char *orig, struct cifs_sid *csid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
wbcErr wbcrc;
|
|
Packit |
5f9837 |
char *name, *domain, *sidstr;
|
|
Packit |
5f9837 |
enum wbcSidType type;
|
|
Packit |
5f9837 |
struct wbcDomainSid wsid;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
sidstr = strdup(orig);
|
|
Packit |
5f9837 |
if (!sidstr) {
|
|
Packit |
5f9837 |
*plugin_errmsg = "Unable to copy string";
|
|
Packit |
5f9837 |
return -ENOMEM;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
name = strchr(sidstr, '\\');
|
|
Packit |
5f9837 |
if (!name) {
|
|
Packit |
5f9837 |
/* might be a raw string representation of SID */
|
|
Packit |
5f9837 |
wbcrc = wbcStringToSid(sidstr, &wsid);
|
|
Packit |
5f9837 |
if (WBC_ERROR_IS_OK(wbcrc))
|
|
Packit |
5f9837 |
goto convert_sid;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
domain = "";
|
|
Packit |
5f9837 |
name = sidstr;
|
|
Packit |
5f9837 |
} else {
|
|
Packit |
5f9837 |
domain = sidstr;
|
|
Packit |
5f9837 |
*name = '\0';
|
|
Packit |
5f9837 |
++name;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wbcrc = wbcLookupName(domain, name, &wsid, &type);
|
|
Packit |
5f9837 |
/* FIXME: map these to better POSIX error codes? */
|
|
Packit |
5f9837 |
if (!WBC_ERROR_IS_OK(wbcrc)) {
|
|
Packit |
5f9837 |
*plugin_errmsg = wbcErrorString(wbcrc);
|
|
Packit |
5f9837 |
free(sidstr);
|
|
Packit |
5f9837 |
return -EIO;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
convert_sid:
|
|
Packit |
5f9837 |
wsid_to_csid(csid, &wsid);
|
|
Packit |
5f9837 |
free(sidstr);
|
|
Packit |
5f9837 |
return 0;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
static void
|
|
Packit |
5f9837 |
wuxid_to_cuxid(struct cifs_uxid *cuxid, const struct wbcUnixId *wuxid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
switch(wuxid->type) {
|
|
Packit |
5f9837 |
case WBC_ID_TYPE_UID:
|
|
Packit |
5f9837 |
cuxid->id.uid = wuxid->id.uid;
|
|
Packit |
5f9837 |
cuxid->type = CIFS_UXID_TYPE_UID;
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
case WBC_ID_TYPE_GID:
|
|
Packit |
5f9837 |
cuxid->id.gid = wuxid->id.gid;
|
|
Packit |
5f9837 |
cuxid->type = CIFS_UXID_TYPE_GID;
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
#ifdef HAVE_WBC_ID_TYPE_BOTH
|
|
Packit |
5f9837 |
case WBC_ID_TYPE_BOTH:
|
|
Packit |
5f9837 |
cuxid->id.uid = wuxid->id.uid;
|
|
Packit |
5f9837 |
cuxid->type = CIFS_UXID_TYPE_BOTH;
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
#endif /* HAVE_WBC_ID_TYPE_BOTH */
|
|
Packit |
5f9837 |
default:
|
|
Packit |
5f9837 |
cuxid->type = CIFS_UXID_TYPE_UNKNOWN;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
int
|
|
Packit |
5f9837 |
cifs_idmap_sids_to_ids(void *handle __attribute__((unused)),
|
|
Packit |
5f9837 |
const struct cifs_sid *csid, size_t num,
|
|
Packit |
5f9837 |
struct cifs_uxid *cuxid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
int ret;
|
|
Packit |
5f9837 |
unsigned int i;
|
|
Packit |
5f9837 |
wbcErr wbcret;
|
|
Packit |
5f9837 |
struct wbcDomainSid *wsid;
|
|
Packit |
5f9837 |
struct wbcUnixId *wuxid;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
if (num > UINT_MAX) {
|
|
Packit |
5f9837 |
*plugin_errmsg = "num is too large.";
|
|
Packit |
5f9837 |
return -EINVAL;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wsid = calloc(num, sizeof(*wsid));
|
|
Packit |
5f9837 |
if (!wsid) {
|
|
Packit |
5f9837 |
*plugin_errmsg = "Unable to allocate memory.";
|
|
Packit |
5f9837 |
return -ENOMEM;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wuxid = calloc(num, sizeof(*wuxid));
|
|
Packit |
5f9837 |
if (!wuxid) {
|
|
Packit |
5f9837 |
*plugin_errmsg = "Unable to allocate memory.";
|
|
Packit |
5f9837 |
ret = -ENOMEM;
|
|
Packit |
5f9837 |
goto out;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
for (i = 0; i < num; ++i)
|
|
Packit |
5f9837 |
csid_to_wsid(&wsid[i], &csid[i]);
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* Winbind does not set an error message in the event that some
|
|
Packit |
5f9837 |
* mappings fail. So, we preemptively do it here, just in case.
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
*plugin_errmsg = "Some IDs could not be mapped.";
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
wbcret = wbcSidsToUnixIds(wsid, num, wuxid);
|
|
Packit |
5f9837 |
if (!WBC_ERROR_IS_OK(wbcret)) {
|
|
Packit |
5f9837 |
*plugin_errmsg = wbcErrorString(wbcret);
|
|
Packit |
5f9837 |
ret = -EIO;
|
|
Packit |
5f9837 |
goto out;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
ret = 0;
|
|
Packit |
5f9837 |
for (i = 0; i < num; ++i)
|
|
Packit |
5f9837 |
wuxid_to_cuxid(&cuxid[i], &wuxid[i]);
|
|
Packit |
5f9837 |
out:
|
|
Packit |
5f9837 |
free(wuxid);
|
|
Packit |
5f9837 |
free(wsid);
|
|
Packit |
5f9837 |
return ret;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
int
|
|
Packit |
5f9837 |
cifs_idmap_ids_to_sids(void *handle __attribute__((unused)),
|
|
Packit |
5f9837 |
const struct cifs_uxid *cuxid, size_t num,
|
|
Packit |
5f9837 |
struct cifs_sid *csid)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
int ret = -EIO;
|
|
Packit |
5f9837 |
wbcErr wbcrc;
|
|
Packit |
5f9837 |
size_t i;
|
|
Packit |
5f9837 |
struct wbcDomainSid wsid;
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
for (i = 0; i < num; ++i) {
|
|
Packit |
5f9837 |
switch(cuxid[i].type) {
|
|
Packit |
5f9837 |
case CIFS_UXID_TYPE_UID:
|
|
Packit |
5f9837 |
wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
case CIFS_UXID_TYPE_GID:
|
|
Packit |
5f9837 |
wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
case CIFS_UXID_TYPE_BOTH:
|
|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* In the BOTH case, prefer a user type first and fall
|
|
Packit |
5f9837 |
* back to a group if that doesn't map.
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
|
|
Packit |
5f9837 |
if (WBC_ERROR_IS_OK(wbcrc))
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
|
|
Packit |
5f9837 |
break;
|
|
Packit |
5f9837 |
default:
|
|
Packit |
5f9837 |
csid[i].revision = 0;
|
|
Packit |
5f9837 |
*plugin_errmsg = "Invalid CIFS_UXID_TYPE value";
|
|
Packit |
5f9837 |
continue;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
if (WBC_ERROR_IS_OK(wbcrc)) {
|
|
Packit |
5f9837 |
ret = 0;
|
|
Packit |
5f9837 |
wsid_to_csid(&csid[i], &wsid);
|
|
Packit |
5f9837 |
} else {
|
|
Packit |
5f9837 |
csid[i].revision = 0;
|
|
Packit |
5f9837 |
*plugin_errmsg = wbcErrorString(wbcrc);
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
return ret;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
/*
|
|
Packit |
5f9837 |
* For the winbind plugin, we don't need to do anything special on
|
|
Packit |
5f9837 |
* init or exit
|
|
Packit |
5f9837 |
*/
|
|
Packit |
5f9837 |
int
|
|
Packit |
5f9837 |
cifs_idmap_init_plugin(void **handle __attribute__((unused)), const char **errmsg)
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
plugin_errmsg = errmsg;
|
|
Packit |
5f9837 |
return 0;
|
|
Packit |
5f9837 |
}
|
|
Packit |
5f9837 |
|
|
Packit |
5f9837 |
void
|
|
Packit |
5f9837 |
cifs_idmap_exit_plugin(void *handle __attribute__((unused)))
|
|
Packit |
5f9837 |
{
|
|
Packit |
5f9837 |
return;
|
|
Packit |
5f9837 |
}
|